Certicom? [...] [Fwd: NSA Turns To Commercial Software For
Dr. Robert J. Harley
harley at argote.ch
Mon Oct 27 07:37:55 PST 2003
> > FWIW, this is about going rate for RSA too, BTW.
> Was. RSA's patent has expired.
And ECC never has been and never can be patented. Some protocols and
implementation methods are (just as they are for RSA etc.)
>BTW, the only decent *software* ECC, FEE, is patented, by Apple.
Are you serious? So many holes... so little time...
Let's see. Are you talking about software or about technology?
Re: Software; I have never seen FEE software lauded. Apple uses an
implementation of it in MacOS... other than that... uh...???
Re: Technology; Apples uses it is as a minor PR opportunity to claim
that they are doing crypto research. The patent is an abusive one on
trivia (see below). One day Crandall thought of using simple primes
in ECC (like about 1000 other people) and patented it. NeXT used this
as a PR opportunity to claim that they had developed it on purpose to
avoid licensing RSA. They also said anybody could use FEE without
Then Apple bought NeXT. Dunno what their position is but it is
irrelevant. FEE is bog standard ECC over prime fields, using primes
of the form p = 2^d-c with small c such as 2^233-3. This makes
reduction simpler and speeds up operations a bit. It is absolutely
trivial to pick other simple primes not covered by the patent, such as
p = 2^248-2^100-1. All of the NIST curves over prime fields are of
this form, such as p = 2^224-2^96+1.
Personally, I would avoid such special cases anyway.
/ \ .-. .-. / \
/ \ / \ .-. _ .-. / \ / \
/ \ / \ / \ / \ / \ / \ / \
/ \ / \ / `-' `-' \ / \ / \
\ / `-' `-' \ /
More information about the FoRK